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A protocol for quantum secure direct communication using blocks of EPR pairs is proposed. A set 
of ordered A'' EPR pairs is used as a data block for sending secret message directly. The ordered A'^ 
, EPR set is divided into two particle sequences, a checking sequence and a message-coding sequence. 

' After transmitting the checking sequence, the two parties of communication check eavesdropping 

' by measuring a fraction of particles randomly chosen, with random choice of two sets of measuring 

, bases. After insuring the security of the quantum channel , the sender, Alice encodes the secret 

message directly on the message-coding sequence and send them to Bob. By combining the checking 
and message-coding sequences together. Bob is able to read out the encoded messages directly. The 
, scheme is secure because an eavesdropper cannot get both sequences simultaneously. We also discuss 

. issues in a noisy channel. 

o\ 
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PACS numbers: 03.67.Hk, 03.65.Ud, 03.67.Dd, 03.65.Ta 



> ■ I. INTRODUCTION 

m ■ 

. The goal of cryptography is to ensure that the secret message is inteUigible only for the two authorized parties 
■ of communication and not be altered during the transmission. Thus far, it is trusted that the only proven secure 
crypto-system is the one-time-pad scheme in which the secret key is as long as the message. The two distant parties 
who want to transmit their secret message must distribute the secret key first. But it is difficult to distribute securely 
] the secret key through a classical channel. Quantum key distribution (QKD), the approach using quantum mechanics 
. principle for the distribution of secret key is the only proven protocol for secure key distribution. 

A lot of attention has been focused on QKD and it has been developed quickly since Bennett and Brassard proposed 
^ ' , , the standard BB84 QKD protocols in 1984. Now there have been a lot of theoretical QKD schemes, for instance in 
^ ■ Refs. 0, S H i, S SB SM E III El El El El 111 111 111 • They can be attributed to one of the two types, the 
non-deterministic one and the deterministic one. The feature of the non-deterministic schemes is that the sender, Alice 
^ ■ chooses randomly two sets of measuring bases (there are at least two sets of non-orthogonal bases) to produce two kinds 
of orthogonal states and transmits them to the receiver, Bob. Bob then also chooses randomly one of the two sets of 
bases to measure the states. There are only a certain probability that Alice and Bob choose the same bases. So Alice 
cannot determine which bit value Bob can receive before they exchange classical information. The typical schemes 
are the BB84 IJ, EkertQl 2], BBM92 3] and 6-state protocols|^. In contrast, in the deterministic schemes, Alice and 
• Bob choose the same orthogonal bases for their measurements, so that they get the same results deterministically if 
the quantum channel is not disturbed. Typical such protocols are the ones presented in Refs[5l IgI Isl ITol ITsjl . 

Different from key distribution whose object is to establish a common random key between two parties, a secure di- 
rect communication is to communicate important messages directly without first establishing a random key to encrypt 
them. Thus secure direct communication is more demanding on the security. As a secure direct communication, it 
must satisfy two requirements. First the secret messages should be read out directly by the legitimate user, Bob when 
he receives the quantum states, and no additional classical information is needed after the transmission of qubits. 
Secondly the secret messages which have been encoded already in the quantum states should not leak even though 
an eavesdropper may get hold of channel. That is to say, the eavesdropper can not only be detected but also obtains 
blind results. As classical message can be copied fully, it is impossible to transmit secret messages directly through 
classical channels. But when quantum mechanics enters into the communication, the story will change. 

Recently, Beige et al. proposed a QSDC scheme[l^. In this scheme the message can be read only after a transmission 
of an additional classical information for each qubit. Bostrom and Felbingeer put forward a Ping-Pong QSDC 
scheme|2l|- It is secure for key distribution, quasi-secure for direct secret communication if perfect quantum channel 
is used. However it is insecure if it is operated in a noisy quantum channel, as shown by W6icik|2l]|. There is some 
probability that a part of the message might be leaked to the eavesdropper. Eve, especially in a noisy quantum 
channel. Because Eve can use the intercept-resending strategy to steal some secret message even though Alice and 
Bob will find out her in the end of communication, especially in a noise quantum channel. Moreover the capacity is 
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restricted, and an entangled state (an EPR pair ) only carries one bit of classical information. 

In this paper, we will introduce a QSDC scheme with EPR pairs generalizing the basic ideas in Ref.[l3| in QKD. It 
will be shown that it is provably secure and has high capacity, we discuss the problems in a lossy quantum channel. 

II. THE TWO-STEP QUANTUM SECURE DIRECT COMMUNICATION SCHEME 

An EPR pair can be in one of the four Bell states, 
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Here |0) and |1) are the up and down eigenstate of the cr^, the photon polarization operator. If we measure the 
state of a single photon, the Bell-state will collapse and the state of the other particle will be completely determined 
if we know the measurement result of the first photon. For example, if we measure the state of photon A in the Bell 
state \'4!^) and obtain |0), then the state photon B will collapse to quantum state 

In the QKD protocol in Ref.T^, a set of N ordered EPR pairs, each randomly in one of the 4 Bell-states, is prepared 
and divided into two sequences. Alice transmits the first sequence to Bob, and then they measure a subset of photons 
in their hands respectively. After that, they analyze the security of the transmission for the first sequence. If they 
insure that the channel is safe, Alice sends the second sequence to Bob. Bob then performs Bell-basis measurement 
on the ordered N EPR pair to read out the Bell-states. They perform a second eavesdropping check. By analyzing 
error rate, they can ascertain whether they have safely created a raw key or not. In this protocol, the transmission 
is done in batches of N EPR pairs. An advantage of block-transmission protocol is that we can check the security 
of the transmission by measuring some of the photons in the first step where Alice and Bob each holds a particle 
sequence in the hands. Once the security of the quantum channel is ensured, which means that an eavesdropper has 
not acquired the first particle sequence, then no information will be leaked to her whatever she may do to the second 
particle sequence. 

Because of this property, this two-step QKD scheme can be modified for secure direct communication. Here we 
first give the specific steps of the QSDC protocol, they are 

(1) Alice and Bob agree on that each of the four Bell bases can carry two-qubit classical information, and encode 

!</>") and If/)"*") as 00, 01, 10 and 11, respectively. 

(2) Alice prepares an ordered N EPR pairs in state |V')cm ~ 1^ ) = ^(("^^c |1)m + \^)c |0)m)- We denote the N 
ordered EPR pairs with [(Pi(C),Pi(M)), (P2(C),P2(Af)), (P3(C),P3(M)), ... , (Pjv(C),Pjv(M))]- Here the subscript 
indicates the pair order in the sequence, C and M represent the two particles respectively. 

(3) Alice takes one particle from each EPR pair to form an ordered EPR partner particle sequence, say [Pi(C), 
P2(C), P3(C), ... , PAr(C)]. It is called the checking sequence or simply the C-sequence. The remaining EPR partner 
particles compose another particle sequence [Pi(M), P2(M), P3(M), ... , Pjv(M)], and it is called the message-coding 
sequence or the M-sequence for short. 

(4) Alice sends the C-sequence [Pi(C), P2(C), P3(C), ... , V m{C)] to Bob. Alice and Bob then check eavesdropping 
by the following procedure: (a) Bob chooses randomly a number of the photons from the C-sequence and tell Alice 
which particles he has chosen, (b) Bob chooses randomly one of the two sets of MBs, say az and to measure the 
chosen photons, (c) Bob tells Alice which MB he has chosen for each photon and the outcomes of his measurements, 
(d) Alice uses the same measuring basis as Bob to measure the corresponding photons in the M-sequence and checks 
with the results of Bob's. If no eavesdropping exists, their results should be completely opposite, i.e., if Alice gets 
(1), then Bob gets 1 (0). This is the first eavesdropping check. 

After that, if the error rate is small, Alice and Bob can conclude that there are no eavesdroppers in the line. Alice 
and Bob continue to perform step 5; otherwise they have to discard their transmission and abort the communication. 

(5) Alice encodes her messages on the M-sequence and transmits it to Bob. Before the transmission, Alice must 
encode the EPR pairs. In order to guard for eavesdropping in this transmission, Alice has to add a small trick in 
the M-sequence. She selects randomly in the M-sequence some particles and perform on them randomly one of the 
four operations. The number of such particles is not big as long as it can provide an analysis of the error rate. Only 
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Alice knows the positions of these samphng particles and she keeps them secret until the communication is completed. 
The remaining M-sequence particles are used to carry the secret message directly. To encode the message, we use 
the dense coding scheme of Bennett and Wiesnerj23 where the information is encoded on an EPR pair with a local 
operation on a single qubit. Here we generalize the dense coding idea into secure direct communication. Different 
from dense coding, in this protocol, the both particles in an EPR are sent from Alice to Bob in two steps, and the 
transmission of EPR pairs are done in block. Explicitly, Alice makes one of the four unitary operations {Uq, Ui, U2 
and U3) to each of her particles. 



Uo -/-|0)(0| + |1)(1|, (5) 

C/i -a, = |0)(0|-|1>(1|, (6) 

U2 -a,-|l)(0| + |0)(l|, (7) 

C/3 -ia, = |0)(l|-|l)(0| (8) 



and they transform the state jV'^) into \4>^), {i/j^), \(f>^), \(f>'^) respectively. These operations correspond to 00, 01, 
10, 11 respectively. 

(6) After the transmission of M-sequence, Alice tells Bob the positions of the sampling pairs and and the type of 
unitary operations on them. Bob performs Bell-basis measurement on the C- and M-sequences simultaneously. By 
checking the sampling pairs that Alice has chosen, he will get an estimate of the error rate in the M-sequence trans- 
mission. In fact, in the second transmission. Eve can only disturb the transmission and cannot steal the information 
because she can only get one particle from an EPR pair. 

(7) If the error rate of the sampling pairs is reasonably low, Alice and Bob can then entrust the process, and 
continue to correct the error in the secret message using error correction method. Otherwise, Alice and Bob abandon 
the transmission and repeat the procedures from the beginning. 

(8) Alice and Bob do error correction on their results. This procedure is exactly the same as that in QKD. However, 
to preserve the integrity of the message, the bits preserving correction code, like cascade j2^, should be used. 

As discussed above, Alice and Bob can ensure the security of the C-sequence and Eve will be found out if she 
eavesdrops the quantum line. It is of interest that Eve cannot read out the information in the EPR pairs even if she 
captures one of the two sequences, because no one can read the information from one particle of an EPR pair alone. 
In this way, no secret message will be leaked to Eve. It is secure. Moreover, the capacity is high in this protocol, 
because each of EPR pair carries two bits of classical information. 

III. SECURITY OF THE QSDC SCHEME 

Our QSDC protocol bases on EPR pair, so the proof of security is similar to those in Refs. [201 123 . with entangled 
photons. The proof for the security of our QSDC protocol is based on the security for the transmission of the C- 
sequence. If Alice and Bob could not detect eavesdropper (Eve)in the transmission of the C-sequence, Eve would 
capture easily the two photons in each EPR pair and take Bell-basis measurement on them to read out the secret 
message. 

The transmission and the security check of the C-sequence in our QSDC protocol is similar to the procedures in 
BBM92 QKD protocol^, where one particle in an EPR pair is sent to Alice and the other is sent to Bob. Here the 
M-sequence particles are retained securely in Alice's site. Before checking eavesdropping. Eve has no access to the 
M-sequence particles. Therefore the security of transmission for the C-sequence simply reduces to the security of the 
BBM92 QKD protocol. The proof of security for BM92 in ideal condition is done in Ref. 22] and that with practical 
conditions was given in detail in Ref.[23|. Hence our QSDC protocol is secure.. 

Now, let us give the reason that why we choose two sets of measuring basis for checking the security of the 
transmission for the C-sequence. According to Stinespring dilation theorem, as Eve is limited only to eavesdropping 
on the quantum line between Alice and Bob, her eavesdropping can be realized by a unitary operation, say E' on a 
larger Hilbert space, \b, E) = \E). Then the state of composite system Alice, Bob and Eve is 

m= E (9) 

a,b£{0,l} 

where |eo,b) describes Eve's probe state, and \a) and |6) are single photon states of Alice's and Bob's in an each EPR 
pair, respectively. As in Ref.fl^l, the condition on the states of Eve's probe is 



a, 66(0,1} 



(10) 
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As Eve can only eavesdrop the C-sequence before the first checking, we can describe Eve's effect on the system as 



|0, E) = \0)g \E) = a \0)g \eoo) + P \l) b koi) = « |0, eoo) + /5 11, eoi) , 
|1,£;) EE 11)^ \E) ^ p 11)5 |eio) +« \1)b kii) = P |0,eio) + « |l,eii> 
i.e, Eve's probe can be modelled by 

Since E has to be unitary, the complex numbers a, (3, a and [3 must satisfy 
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We get the following relations 
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For Alice and Bob, the action of Eve's eavesdropping will introduce an error rate 
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If Eve can only capture one photon in each EPR pair, she gets no information. The way Eve can steal information 
is that she pretend Bob to receive the C-sequence and send a fake sequence to Bob. If Alice and Bob could not find 
out her action, Eve would intercept the M-sequence and read out the information in the EPR pairs. That is to say, 
only when Alice and Bob ascertain that there is no eavesdropper monitoring the quantum line, they transmit the 
M-sequence. We can calculate the information Eve can maximally gain. When the C-sequence particles reach Bob, 
its reduced density matrix is 



Pb = TrAipAs) 



TrA{\'ip)ABAB (^1) = ^(01 



(17) 



that is to say, Bob's photon can be in either state |0) or |1) with equal probability P ~ \. 

Similar to that in Ref.|23], first let us suppose that the quantum state of the photon in the hand of Alice is |0), i.e., 
Alice takes measurement on the photon in her hand with single photon detector and the state is |0). Then the state 
of the system composed of Bob's photon and Eve's probe can be described by 



^P)=E\Q,E) = E |0)b \E) - a |0)s koo) + /? |1)b koi) = « |0, £00) + /3 |1, ^oi) , 



(18) 



p ^ \a\^ |0,eoo) (0,eoo| + 



|l,eoi) (l,£oi| 



v/3* |0, £00) (1, Soil + |1, £01) (0, £oo| • 



(19) 



After encoding of the unitary operations C/q, Ui, U2 and U3 with the probabilities po, Pi, P2 and ^3 respectively, 
the state reads 



p" = (po+P3)|a|'|0,£oo)(0,£oo| + (po+P3)|/3|'|l,eoi)(l,eoi| (20) 
+ {po -PziaP* |0,eoo) (l,£oi| + (po - Pa)"*/? |1, £01) (0,eoo| 
+ (pi +P2) |l,eoo) (l,eoo| + {pi + P2) |0,eoi) (O,eoi| 
+{pi -P2)aP* |l,£oo) (0,£oi| + {pi -P2)a*/3|0,eoi) (l,£oo| 
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which can be rewritten in the orthogonal basis {|0, eoo) , |l,£oi) , 11, ^oo) , |0, eoi)}: 



P = 



f{po+P3)\af {po-P3)a(3* 

(po-P3)a*/3 {Po+P3)\P\^ 

{pi+p2)\af {pi-p2)a(3* 

V ipi-p2)a*0 (Pi+P2)|/3|V 



(21) 



where po + Pi + P2 + Pa = 1 • 

The information Iq that Eve can get is equal to the Von Neumann entropy, i.e, 



/o = ^-Aaog2A, (22) 



i=0 



where A^ (1=0,1,2,3) are the eigenvalues of p , which are 



Ao,i = liPo+Ps) ± lViPo+P3r - IGpoPMW (23) 
= ^{Po +P3) ± ^ViPo+Ps)'^ - 16poP3(e - e^), 

A2,3 = \{Pi +P2) ± IViPi +P2? - lQpiP2\a\^W (24) 
1 , ,1 



= ^{Pi +P2) ± -^ViPi +P2Y - 16piP2(e - e^)- 

If the four operations distribute with equal probability, that Po = Pi = P2 — P3 — \i Eve can get 1 bit of information 
from each EPR pair with the error rate e = 0. In fact, the simple way for Eve to steal information is that Eve measures 
each photon with MB and Alice and Bob cannot find out the action of Eve's. Even though Eve cannot read out 
the information of phase in EPR pair, she can distinguish the value of each bit. That is to say, she can distinguish 
the operations {Uq^Ui} from {J72, C^s}- This is an intrinsic limitation on the coding in Ref . [20l| . 

Surely the proof and the above discussion are based on ideal condition and do not take into account noise in 
transmission. In fact, in low noise channel, the photon loss will be small, and Eve's action will increase either the 
error rate or loss of signal, so the security of C-sequence is assured if Alice and Bob do the first eavesdropping check and 
analyze the error rate and the efficiency. On the contrary, if quantum channel loss is sufficiently high, two problems 
arise. The first one is the security of transmission of the C-sequence which requires Alice and Bob share a sequence 
of entangled states securely. The other is the loss of the M-sequence. Without measurement Bob cannot make sure 
whether he receives the particles or not in the C-sequence and Alice must encode all particles in M-sequence. In this 
way. Eve's eavesdropping cannot be detected if she captures some of particles in C-sequence and sends the others to 
Bob with a better quantum channel with which the lossy efficiency of all the photons is not increased. Eve intercepts 
the M-sequence and do Bell-basis measurement and then gets some of the secret message. This is the danger of not 
sharing a sequence of EPR pairs securely. In order to avoid the attack on C-sequence and share a sequence of EPR 
pairs securely. Bob can perform quantum entanglement swapping 24] on the particles he receives first and then gets 
a subset of C-sequence of particles entangled with Alice's(called the C'-sequence): if there are indeed particles there, 
the swapping will succeed otherwise the swapping will fail. The swapping operation here serves as a particle existence 
detection. Then Bob chooses randomly a subset of the C'-sequence particles and measures them with either az or 
(Jx- Alice only encodes on the subset of M-sequence corresponding to the sub-C-sequence(called the M'-sequence) 
on which Bob succeeds in quantum entanglement swapping. With these two procedures Alice and Bob can share a 
sub-sequence of EPR pairs truly and the action of Eve's can be detected even in a highly lossy quantum channel. In 
practical applications, some coding using redundancy is necessary as has been extensively in classical communications. 
For instance, several bits mayve used to code a single bit for instance using the CSS coding method|i26.]. In this way, 
Alice and Bob must pay a lot of source for the correlated results. 



IV. IMPLEMENTATION ISSUES 



In our scheme, we need to store the checking sequence of photons for a while, to make eavesdropping check and wait 
for the M-sequence of photons to come. This is the price to pay for the improved security and enhanced efficiency. 
Here we propose two ways to realize this. One is using light storage device, and the other is to use optical delays. 



6 



It has already been demonstrated experimentally that light can be stored together with their quantum states[23,l23- 
With the electromagnetic induced transparency technique, the C-sequence of photons can be stored for a while to 
complete the eavesdropping check and the travelling of the M-sequence. At present, the technique may not be mature 
enough for a practical implementation of the proposed QSDC scheme. However, as it may be the only light storage 
device, together with its roles in quantum computation, it is extremely demanding that this technique be developed 
further. 

Another realization is to use optical delays. This is a well developed technology and is experimentally feasible. 
Instead of producing an ordered EPR pairs in space at the same time, we can produce a time ordered EPR pair 
sequence. As shown in Fig. 2, a sequence of EPR pairs are produced at Alice's site. One after another photon in the 
C-sequence is sent to Bob's site through the upper line first. The corresponding M-sequence is sent to Bob through the 
lower transmission line. However, the M-sequence is delayed by r at Alice's site before it enters the insecure channel. 
When the C-sequence reaches Bob, Bob selects randomly some photons for eavesdropping check. He measures those 
chosen photons randomly in the Ux or Uz basis and he announces publicly the positions, and the measuring-basis and 
the outcomes of the measurement for these chosen photons. After hearing these results, Alice performs measurement 
using the same measuring-basis as Bob's on the corresponding photons in the M-sequence. If the error rate is below a 
predetermined threshold, she concludes that the quantum channel is secure and preforms coding unitary operation on 
the M-sequence particles. During the M-sequence transmission, some randomly chosen photons are used to check the 
transmission error rate. In these chosen sampling photons, an operation randomly chosen form the four operations is 
applied. Therefore after Bob receives the sampling pairs and combines with his partner photons in the C-sequence, 
he can recover these operations using Bell-basis measurement. These sampling pairs will give an error rate estimate 
of the second transmission, and this error rate will be used as a parameter later in error correction process. 

A very important quantity is the delay r. It depends on the distance between Alice and Bob, the number N in each 
block, and the number of photons transmitted per unit time, /. For simplicity, we ignore the times it takes for the 
eavesdropping check measurement, and the coding operation. Then t must be long enough for a photon to travel to 
Bob, and Bob makes measurement and tells Alice the result, and then sends the M-sequence particles to Bob. Thus 
it must be 3 times of the period for a photon to travel from Alice to Bob. If this has to be done for a block of N pairs, 
additional time y has to be added. Thus the delay should be 



?,L N 

T>— + ^ 25 

where L is the distance between Alice and Bob, and c is the velocity of light in quantum channel. Complete Bell-basis 
measurement is also highly demanding, and has been demonstrated recently j22||. 



V. DISCUSSION AND SUMMARY 



The presented scheme resembles more to a quantum key distribution protocol. In fact, after Bob receives the 
checking sequence, Alice and Bob can establish a common one-time-pad key by measuring their particles using a 
randomly chosen basis from the ct^ or cr^ basis, which is a variant of the Ekert910 QKD and the BBM920 QKD 
protocol. Then the secret message can be encoded using this one-time-pad key and transmitted through a classical 
channel. The important distinction between quantum direct communication and the quantum key distribution scheme 
is that in the quantum direct communication scheme no classical key is ever established, but rather an inherently 
quantum mechanical resource (the shared EPR pairs) takes over the role of the key. With the development of efficient 
EPR source and Bell-state measurement device, quantum direct communication may become easier to realize and be 
favored in some specific applications. 

In summary, a novel QSDC scheme is proposed and secret messages can be coded directly over a quantum channel 
with security. In this scheme, A block of entangled particles is divided into two sequences, the checking sequence 
and message-coding sequence. They are sent from Alice to Bob in two steps. The security is assured by the secure 
transmission of the checking sequence. Moreover, the scheme makes full use of the 2-qubit in an EPR pair. We also 
propose concrete experimental setup for its realization. The scheme is completely secure for an ideal noiseless channel, 
and it conditionally secure with a noisy channel. 
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